Skip to content
Discussion options

You must be logged in to vote

Once I removed my comments syncing had no issue applying the new BPFs. Is there a way to add comments within the GUI to keep track of why new filters were added?

This should work better in the upcoming 2.4.30 release:
#11738
https://docs.securityonion.net/en/2.4/bpf.html#adding-comments

Also once a BPF is applied, is there a way to drop alerts already written to disk that pertain to that filter? or do I just wait for it to be overwritten?

You can manually acknowledge the alerts or wait for the data to be overwritten.

After adding the second filter not (host10.129.5.4 and dst port 161 and dst net 10.129.5.0/24) && I am still showing new data being written to disk that I'm attempting t…

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
4 replies
@HundleBun
Comment options

@argwfm
Comment options

@TOoSmOotH
Comment options

@argwfm
Comment options

Answer selected by HundleBun
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
4 participants